# POL-073 — The policy should say the brand does not use rented or purchased lists

> The policy or SMS terms should state affirmatively that the brand does not message rented, sold or shared opt-in lists.

- **Rule ID:** POL-073
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy or SMS terms body`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** CTIA
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-073/

## Why this rule exists

CTIA asks senders not to use such lists, and the affirmative statement is what a reviewer can actually check — the absence of purchased numbers is not visible in any document. It also matters to the consumer question underneath: someone receiving a message wants to know how the sender got their number, and this is the sentence that answers it.

## How to fix it

Add a sentence to the messaging section stating that every number was collected directly from the person it belongs to and that no rented, purchased or shared lists are used. Done when the document says where the numbers come from.

## Example of a compliant value

```text
Every number in the Acme Coffee text programme was given to us directly by its owner. We do not rent, buy or use lists of numbers collected by anyone else.
```

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Bandwidth | `7108` | yes |
